CVE-2023-39533 is a resource exhaustion vulnerability affecting go-libp2p, the Go implementation of the libp2p Networking Stack, in versions prior to 0.27.8, 0.28.2, and 0.29.1. A malicious peer can exploit this by presenting large RSA keys during the Noise handshake or x509 extension verification, forcing the node to expend significant resources on signature verification. With a CVSS score of 7.5 (HIGH), this network-based attack requires low complexity and can lead to high availability impact. There are no known active exploits, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.27.8CPE matchmatch criteria | cpe:2.3:a:libp2p:go-libp2p:*:*:*:*:*:go:*:* | ||
>= 0.28.0, < 0.28.2CPE matchmatch criteria | cpe:2.3:a:libp2p:go-libp2p:*:*:*:*:*:go:*:* | ||
0.29.0CPE matchmatch criteria | cpe:2.3:a:libp2p:go-libp2p:0.29.0:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libp2p nodes vulnerable to attack using large RSA keys
Aug 9, 2023libp2p nodes vulnerable to attack using large RSA keys
Aug 8, 2023go-libp2p: libp2p nodes vulnerable to attack using large RSA keys
Aug 8, 2023